{"id":"CVE-2026-59884","aliases":["GHSA-m4p7-r5rc-7g4j","PYSEC-2026-3455"],"url":"https://o3.security/vulnerability/CVE-2026-59884","summary":"pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs","details":"pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses long-form tags by accumulating continuation octets without an upper bound on the tag ID size, allowing a crafted input to force construction of an arbitrarily large integer with CPU cost growing quadratically and to trigger unhandled ValueError exceptions in Python 3.11+ error formatting paths. Any application decoding untrusted BER, CER, or DER input is affected. This issue is fixed in version 0.6.4.","published":"2026-07-14T16:41:10.277Z","modified":"2026-08-22T18:49:59.361296181Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":{"score":0.00349,"percentile":0.27542,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"pyasn1","fixedVersion":"0.6.4"}],"fix":{"url":"https://github.com/pyasn1/pyasn1/commit/628e36ecbb5277a3f01572ce418ef54271b165a5","label":"pyasn1/pyasn1@628e36e"},"references":[{"type":"WEB","url":"https://github.com/pyasn1/pyasn1/releases/tag/v0.6.4"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59884.json"},{"type":"ADVISORY","url":"https://github.com/pyasn1/pyasn1/security/advisories/GHSA-m4p7-r5rc-7g4j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59884"},{"type":"FIX","url":"https://github.com/pyasn1/pyasn1/commit/628e36ecbb5277a3f01572ce418ef54271b165a5"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-22T18:49:59.361296181Z"}}